Internal Audit Procedures

Written By Micah

ISO 27001:2022, Clause 9.2 Performance evaluation, requires that the organization's information security (and privacy management system) shall be internally audited at planned intervals. This template provides the procedures to be followed for the Internal Audit of the ISMS (and PIMS)

Commonly associated evidence:

  • Internal Audit

Who needs a policy like this?

  • Organizations that adhere to ISO 27001 and ISO 27701

How to use the template:

  • Click on the link above to access the template

    • If you are a Google Workplace organization, make a copy by going to File > Make a copy

    • If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)

  • Review and then remove instructional text

  • Save in a centralized place

  • Attach to evidence either through Integrations, Automated Collection, or direct upload

If you need help using the template, please let us know.